The White House Named Moonshot, Its Chips, and the Model It Allegedly Copied. The Researchers Aren’t Convinced.


On July 22, the director of the White House Office of Science and Technology Policy stood up and did something the U.S. government had never done before with an AI model. Michael Kratsios named the company, named the American model it allegedly copied, and named the banned chips it allegedly used to do it. Moonshot AI, he said, built Kimi K3 by running “large-scale distillation against U.S. models,” specifically Anthropic’s Fable, and it trained on Nvidia GB300 servers it was never supposed to be able to touch, some of them reached through Thailand.

Within a day, Treasury Secretary Scott Bessent had put sanctions and Entity List designations on the table. And within the same day, the people who actually build frontier models, plus the CEO of the company whose chips are at the center of the whole thing, had started telling reporters the technical story does not hold together.

That gap between the accusation and the engineering is the real story here.

What the government actually alleged

Kratsios laid out two separate claims, and it is worth keeping them apart because they carry very different weight.

The first is the distillation claim. Moonshot, he said, “developed a sophisticated internal platform to conduct large-scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” Distillation, in the plain sense, is training a smaller or newer model on the outputs of a larger one so it inherits the bigger model’s behavior. The target he named was Fable, Anthropic’s Mythos-class flagship, which only became publicly available on July 1. Moonshot released Kimi K3 as open weights roughly two weeks later.

The second is the hardware claim. Kratsios said Moonshot “acquired Nvidia’s GB300-equipped servers and has accessed GB300s in Thailand, likely to train its AI models.” The GB300 is Blackwell-generation silicon, barred from sale to Chinese firms. Routing compute through a third country to sidestep that ban is a direct export-control problem, and it is the part of the accusation with the clearest legal teeth.

Bessent tied a consequence to both. “Open source is not open season on American IP,” he told Fox Business. “When firms conduct covert, industrial-scale distillation attacks that cross the line into IP theft, sanctions and Entity List designations will be on the table.”

Kratsios drew the same line the administration has drawn before: legitimate distillation to make smaller, cheaper models is fine and even healthy for the ecosystem, but “large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.” He offered no public evidence for how the government concluded Kimi K3 was derived from Fable. Neither Moonshot nor Nvidia responded to requests for comment.

Why the researchers aren’t buying it

Here is where it gets interesting, because the pushback did not come from Beijing. It came from American AI researchers with no obvious reason to defend a Chinese lab.

Braden Hancock of the Laude Institute and Snorkel AI went straight at the timeline. “I don’t think you get a model this strong and this quickly on the heels of Fable doing strictly distillation,” he said. Fable went public July 1. Kimi K3 shipped about two weeks later. That window has to contain generating a massive volume of teacher outputs, running a full training cycle on a 2.8-trillion-parameter mixture-of-experts model, evaluating it, and releasing the weights. Distillation at that scale is not a weekend job.

Nathan Lambert at the Allen Institute for AI made the deeper point about what distillation can and cannot buy you. Supervised fine-tuning on another model’s outputs helps a weak model a lot and a strong model much less. If simply distilling a frontier model produced a frontier model, he noted, everyone would already be doing it and the field would have collapsed into a tie. “We have not, or we won’t see this, from supervised fine-tuning alone.”

There is also an infrastructure problem the accusation glosses over. The version of distillation that actually moves a model toward the frontier, using reinforcement learning with the teacher grading millions of candidate responses, would require tens of millions of API calls to Fable. At Fable’s price and speed, that is both wildly expensive and slow enough to bottleneck the whole effort, which is the opposite of the two-week sprint the government described. Hancock’s alternative explanation is the boring one: Moonshot employs real researchers doing real work, including a founder who came out of a CMU PhD program, and Kimi K3 is good because they are good.

Then there is Jensen Huang. On the same news cycle in which his own company’s banned chips were being cited as evidence of Chinese cheating, the Nvidia CEO called open models like Kimi “excellent” and argued the United States should embrace them rather than ban them. When the person with the most to gain from a China crackdown is publicly waving it off, the official narrative is under real strain.

This is not the first distillation accusation, and that pattern matters

Anthropic has been here before. In June, it told the Senate that Alibaba had run 28.8 million queries through roughly 25,000 fraudulent accounts against Claude over six weeks, an operation it read as coordinated distillation harvesting. Back in April, OpenAI, Anthropic, and Google jointly flagged distillation as a national concern through the Frontier Model Forum. And in June the government showed it would act on the compute side too, when it made Fable 5 the first frontier model recalled under export-control pressure days after launch.

Put those together and a strategy comes into focus. The U.S. cannot stop a lab in Beijing from calling an API or buying secondhand servers in Bangkok. What it can do is raise the cost of getting caught, name names loudly enough to spook investors and partners, and keep the Entity List hanging over anyone who might otherwise route around the chip ban. The Moonshot accusation reads less like the conclusion of an investigation and more like the opening move in a deterrence campaign.

What a practitioner should take from this

I run enterprise AI infrastructure, and the reflex when a story like this breaks is to ask whether it changes anything about the model you were about to deploy. Mostly it does not, and it is worth being precise about why.

The distillation fight is about how Kimi K3 was made, not about whether the weights on your disk work. If K3 clears your evaluations on cost per completed task, it will keep clearing them regardless of how the training data was sourced. This is the same calculus that applies to any open-weight model you self-host: the provenance debate and the production decision are different questions.

The export-control piece is the one that can actually reach you, and it reaches you through supply, not through ethics. If Washington puts Moonshot on the Entity List, the risk is not that Kimi K3 becomes illegal to run. It is that future models from the same lab, and the API endpoints and hosted inference behind them, become unstable dependencies. We have watched this movie with the broader Chinese open-weight wave, from GLM trained on Huawei silicon to Meituan’s LongCat running on domestic chips. The models are genuinely good. The vendor relationships sit on a geopolitical fault line. If you are betting a production workload on one, keep a domestic fallback wired and tested, because the switch may get thrown by a policy decision you have no visibility into.

The part I would not do is treat the government’s technical claim as settled. When the researchers who understand distillation and the executive who sells the chips both say the story is thinner than advertised, the honest read is that we have a serious export-control allegation wrapped inside a shakier IP-theft narrative. Those two things deserve different levels of belief. Nvidia lost its entire China business to export controls last year and grew revenue 85% anyway, which is a useful reminder that the compute ban is real and consequential even when the copying story is in doubt.

The escalation is here either way. A White House that will name a specific foreign lab, a specific American model, and a specific banned chip in one statement has decided the open-weight race is a national-security file, not a research curiosity. What it has not yet produced is the evidence that Kimi K3 is a copy rather than a competitor. Until it does, the smartest position is the one the builders are already taking: take the export-control risk seriously, and take the theft claim with a grain of salt.

Ty Sutherland

Ty Sutherland is the Chief Editor of AI Rising Trends. Living in what he believes to be the most transformative era in history, Ty is deeply captivated by the boundless potential of emerging technologies like the metaverse and artificial intelligence. He envisions a future where these innovations seamlessly enhance every facet of human existence. With a fervent desire to champion the adoption of AI for humanity's collective betterment, Ty emphasizes the urgency of integrating AI into our professional and personal spheres, cautioning against the risk of obsolescence for those who lag behind. "Airising Trends" stands as a testament to his mission, dedicated to spotlighting the latest in AI advancements and offering guidance on harnessing these tools to elevate one's life.

Recent Posts